Compliance Document

DPDP Compliance

Digital Personal Data Protection Act, 2023

Last Updated: January 15, 2025
1
Section 1

Introduction to DPDP Act

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's comprehensive data protection legislation that governs the processing of personal data. At Whats91, we are fully committed to complying with the DPDP Act and protecting the personal data of our users.

This compliance statement outlines how we adhere to the principles and requirements set forth in the DPDP Act, ensuring transparency, accountability, and security in all our data processing activities.

2
Section 2

Our Role and Responsibilities

Under the DPDP Act, Whats91 acts as a Data Fiduciary for the personal data collected directly from users, and as a Data Processor when processing data on behalf of our enterprise clients.

  • As Data Fiduciary: We determine the purpose and means of processing personal data collected through our website and services
  • As Data Processor: We process personal data on behalf of enterprise clients who use our WhatsApp API solutions, following their instructions and our data processing agreements
  • Significant Data Fiduciary: We maintain enhanced compliance measures as we process substantial volumes of personal data through our platform
3
Section 3

Lawful Basis for Processing

We process personal data only when we have a lawful basis under the DPDP Act:

  • Consent: Obtained freely, specifically, informed, and unconditional for specific processing purposes
  • Contractual Necessity: Processing necessary for performance of a contract with the data principal
  • Legal Obligation: Processing required to comply with applicable laws and regulations
  • Legitimate Purpose: Processing for purposes that are reasonably expected by the data principal
4
Section 4

Data Principal Rights

We ensure that all Data Principals (individuals whose data we process) can exercise their rights under the DPDP Act:

  • Right to access information about their personal data and processing activities
  • Right to correction and erasure of inaccurate or incomplete personal data
  • Right to data portability in a machine-readable format
  • Right to withdraw consent at any time
  • Right to be informed about processing activities and purposes
  • Right to lodge complaints with the Data Protection Board of India

To exercise these rights, Data Principals can contact us through our designated grievance officer at dpo@whats91.com.

5
Section 5

Data Collection and Purpose Limitation

5.1 Types of Data Collected

We collect only personal data that is necessary for specified, explicit, and legitimate purposes: contact information, business details, usage data, and communication records.

5.2 Purpose Limitation

Personal data is processed only for the purposes for which it was collected. We do not process data in a manner incompatible with those purposes without obtaining additional consent.

5.3 Data Minimization

We collect only the minimum personal data necessary to fulfill the specified purposes. We do not collect or retain excessive data beyond what is required.

7
Section 7

Data Security Measures

We implement comprehensive security safeguards to protect personal data from unauthorized access, disclosure, alteration, or destruction:

  • Encryption: All personal data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based access controls with multi-factor authentication for all systems
  • Security Audits: Regular security assessments, penetration testing, and vulnerability scans
  • Incident Response: Documented incident response procedures with notification protocols
  • Employee Training: Regular data protection and security awareness training for all personnel
8
Section 8

Data Breach Notification

In the event of a personal data breach, we have established procedures to:

  • Assess the severity and scope of the breach within 48 hours
  • Notify the Data Protection Board of India within 72 hours of becoming aware of a notifiable breach
  • Inform affected Data Principals without undue delay if the breach is likely to result in adverse effects
  • Document all breaches and remedial actions taken
  • Implement measures to prevent similar breaches in the future
9
Section 9

Data Retention and Deletion

Personal data is retained only for as long as necessary for the purposes for which it was collected:

  • Active Account Data: Retained while the account is active and for a defined period thereafter for legitimate business purposes
  • Legal Retention: Data required for legal compliance may be retained for the period mandated by applicable laws
  • Deletion Requests: Upon request from a Data Principal or upon account deletion, we securely delete or anonymize personal data within 30 days
10
Section 10

Cross-Border Data Transfers

The DPDP Act restricts the transfer of personal data outside India. We ensure compliance by:

  • Maintaining primary data storage within India
  • Only transferring data to countries not restricted by the Central Government
  • Implementing standard contractual clauses for any international transfers
  • Ensuring adequate protection measures are in place for transferred data
  • Informing Data Principals about international transfers in our privacy notices
11
Section 11

Grievance Redressal

We have appointed a Data Protection Officer (DPO) to handle data protection matters and grievances:

  • DPO Contact: Data Protection Officer can be reached at dpo@whats91.com
  • Response Time: We acknowledge grievances within 48 hours and respond substantively within 30 days
  • Escalation: If unsatisfied with our response, Data Principals can approach the Data Protection Board of India
12
Section 12

Children's Data

We do not knowingly process personal data of children below the age of 18 years without verifiable consent from their parent or guardian. Our services are intended for businesses and adults. If we become aware that we have processed a child's data without appropriate consent, we will take immediate steps to delete such data.

13
Section 13

Updates to This Compliance Statement

We will update this DPDP Compliance Statement as needed to reflect changes in our practices, technology, legal requirements, and other factors. We will notify users of any material changes through our website or other appropriate means.

14Section 14

Contact Our DPO

For any questions about our DPDP compliance or to exercise your data protection rights, please contact our Data Protection Officer.

We are committed to protecting your personal data in compliance with the DPDP Act, 2023.